PT-2025-1350 · Bitdefender · Bitdefender Antivirus Free 2020
Gábor Selján
·
Published
2025-01-15
·
Updated
2025-01-15
·
CVE-2020-8094
CVSS v4.0
8.8
High
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Bitdefender Antivirus Free 2020
Description
An untrusted search path vulnerability in testinitsigs.exe allows a low-privilege attacker to execute code as SYSTEM via a specially crafted DLL file. This issue enables an attacker to gain elevated privileges.
Recommendations
For Bitdefender Antivirus Free 2020, update to a version that includes a fix for this issue, as using a specially crafted DLL file can lead to code execution with SYSTEM privileges. As a temporary workaround, consider restricting access to the testinitsigs.exe file to minimize the risk of exploitation.
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bitdefender Antivirus Free 2020